{"api_version":"1","generated_at":"2026-07-23T11:06:08+00:00","cve":"CVE-2019-10134","urls":{"html":"https://cve.report/CVE-2019-10134","api":"https://cve.report/api/cve/CVE-2019-10134.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10134","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10134"},"summary":{"title":"CVE-2019-10134","description":"A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-06-26 19:15:00","updated_at":"2021-10-28 12:20:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://moodle.org/mod/forum/discuss.php?d=386524","name":"https://moodle.org/mod/forum/discuss.php?d=386524","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Moodle.org: MSA-19-0012: Private files uploaded via incoming mail processing could bypass quota restrictions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1716610 – (CVE-2019-10134) CVE-2019-10134 moodle: Private files uploaded via incoming mail processing could bypass quota restrictions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10134","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10134","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10134","vulnerable":"1","versionEndIncluding":"3.1.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10134","vulnerable":"1","versionEndIncluding":"3.4.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10134","vulnerable":"1","versionEndIncluding":"3.5.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10134","vulnerable":"1","versionEndIncluding":"3.6.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10134","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Moodle","product":{"product_data":[{"product_name":"moodle","version":{"version_data":[{"version_value":"3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20"}]}]},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134","refsource":"CONFIRM"},{"url":"https://moodle.org/mod/forum/discuss.php?d=386524","name":"https://moodle.org/mod/forum/discuss.php?d=386524","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded."}]},"impact":{"cvss":[[{"vectorString":"4.2/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","version":"3.0"}]]}},"nvd":{"publishedDate":"2019-06-26 19:15:00","lastModifiedDate":"2021-10-28 12:20:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndIncluding":"3.1.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0","versionEndIncluding":"3.4.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndIncluding":"3.5.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6.0","versionEndIncluding":"3.6.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10134","Ordinal":"148351","Title":"CVE-2019-10134","CVE":"CVE-2019-10134","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10134","Ordinal":"1","NoteData":"A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10134","Ordinal":"2","NoteData":"2019-06-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10134","Ordinal":"3","NoteData":"2019-06-26","Type":"Other","Title":"Modified"}]}}}